cbcvebase.
CVE-2006-5806
published 2006-11-08

CVE-2006-5806: SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session…

PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.34%
26.3th percentile
SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files outside of the vault, which is not cleared after the VPN connection terminates and allows local users to read unencrypted data.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscosecure_desktop<= 3.1.1.33
ciscosecure_desktop

CVSS provenance

nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.